The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Inspireui
Inspireui mstore Api |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Inspireui
Inspireui mstore Api |
Fri, 13 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fluxbuilder
Fluxbuilder mstore Api |
|
CPEs | cpe:2.3:a:fluxbuilder:mstore_api:*:*:*:*:*:*:*:* | |
Vendors & Products |
Fluxbuilder
Fluxbuilder mstore Api |
|
Metrics |
ssvc
|
Fri, 13 Sep 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated. | |
Title | MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration | |
Weaknesses | CWE-284 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-13T15:10:38.839Z
Updated: 2024-09-13T18:05:46.615Z
Reserved: 2024-08-28T17:34:13.175Z
Link: CVE-2024-8269
Vulnrichment
Updated: 2024-09-13T18:04:58.289Z
NVD
Status : Analyzed
Published: 2024-09-13T15:15:17.050
Modified: 2024-09-18T15:20:44.553
Link: CVE-2024-8269
Redhat
No data.